-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat(helm): update external-secrets ( 0.9.14 → 0.10.3 ) #147
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/external-secrets-0.x
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
--- HelmRelease: security/external-secrets ClusterRole: security/external-secrets-cert-controller
+++ HelmRelease: security/external-secrets ClusterRole: security/external-secrets-cert-controller
@@ -20,15 +20,23 @@
- patch
- apiGroups:
- admissionregistration.k8s.io
resources:
- validatingwebhookconfigurations
verbs:
- - get
- list
- watch
+ - get
+- apiGroups:
+ - admissionregistration.k8s.io
+ resources:
+ - validatingwebhookconfigurations
+ resourceNames:
+ - secretstore-validate
+ - externalsecret-validate
+ verbs:
- update
- patch
- apiGroups:
- ''
resources:
- endpoints
--- HelmRelease: security/external-secrets ClusterRole: security/external-secrets-controller
+++ HelmRelease: security/external-secrets ClusterRole: security/external-secrets-controller
@@ -36,23 +36,26 @@
- clusterexternalsecrets/status
- clusterexternalsecrets/finalizers
- pushsecrets
- pushsecrets/status
- pushsecrets/finalizers
verbs:
+ - get
- update
- patch
- apiGroups:
- generators.external-secrets.io
resources:
- acraccesstokens
- ecrauthorizationtokens
- fakes
- gcraccesstokens
+ - githubaccesstokens
- passwords
- vaultdynamicsecrets
+ - webhooks
verbs:
- get
- list
- watch
- apiGroups:
- ''
--- HelmRelease: security/external-secrets ClusterRole: security/external-secrets-view
+++ HelmRelease: security/external-secrets ClusterRole: security/external-secrets-view
@@ -26,13 +26,15 @@
- generators.external-secrets.io
resources:
- acraccesstokens
- ecrauthorizationtokens
- fakes
- gcraccesstokens
+ - githubaccesstokens
- passwords
- vaultdynamicsecrets
+ - webhooks
verbs:
- get
- watch
- list
--- HelmRelease: security/external-secrets ClusterRole: security/external-secrets-edit
+++ HelmRelease: security/external-secrets ClusterRole: security/external-secrets-edit
@@ -27,14 +27,16 @@
- generators.external-secrets.io
resources:
- acraccesstokens
- ecrauthorizationtokens
- fakes
- gcraccesstokens
+ - githubaccesstokens
- passwords
- vaultdynamicsecrets
+ - webhooks
verbs:
- create
- delete
- deletecollection
- patch
- update
--- HelmRelease: security/external-secrets Deployment: security/external-secrets-cert-controller
+++ HelmRelease: security/external-secrets Deployment: security/external-secrets-cert-controller
@@ -34,23 +34,26 @@
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
- image: ghcr.io/external-secrets/external-secrets:v0.9.14
+ image: ghcr.io/external-secrets/external-secrets:v0.10.3
imagePullPolicy: IfNotPresent
args:
- certcontroller
- --crd-requeue-interval=5m
- --service-name=external-secrets-webhook
- --service-namespace=security
- --secret-name=external-secrets-webhook
- --secret-namespace=security
- --metrics-addr=:8080
- --healthz-addr=:8081
+ - --loglevel=info
+ - --zap-time-encoding=epoch
+ - --enable-partial-cache=true
ports:
- containerPort: 8080
protocol: TCP
name: metrics
readinessProbe:
httpGet:
--- HelmRelease: security/external-secrets Deployment: security/external-secrets
+++ HelmRelease: security/external-secrets Deployment: security/external-secrets
@@ -34,16 +34,19 @@
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
- image: ghcr.io/external-secrets/external-secrets:v0.9.14
+ image: ghcr.io/external-secrets/external-secrets:v0.10.3
imagePullPolicy: IfNotPresent
args:
- --concurrent=1
- --metrics-addr=:8080
+ - --loglevel=info
+ - --zap-time-encoding=epoch
ports:
- containerPort: 8080
protocol: TCP
name: metrics
+ dnsPolicy: ClusterFirst
--- HelmRelease: security/external-secrets Deployment: security/external-secrets-webhook
+++ HelmRelease: security/external-secrets Deployment: security/external-secrets-webhook
@@ -34,22 +34,24 @@
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
- image: ghcr.io/external-secrets/external-secrets:v0.9.14
+ image: ghcr.io/external-secrets/external-secrets:v0.10.3
imagePullPolicy: IfNotPresent
args:
- webhook
- --port=10250
- --dns-name=external-secrets-webhook.security.svc
- --cert-dir=/tmp/certs
- --check-interval=5m
- --metrics-addr=:8080
- --healthz-addr=:8081
+ - --loglevel=info
+ - --zap-time-encoding=epoch
ports:
- containerPort: 8080
protocol: TCP
name: metrics
- containerPort: 10250
protocol: TCP |
--- kubernetes/apps/security/external-secrets/app Kustomization: flux-system/external-secrets HelmRelease: security/external-secrets
+++ kubernetes/apps/security/external-secrets/app Kustomization: flux-system/external-secrets HelmRelease: security/external-secrets
@@ -13,13 +13,13 @@
spec:
chart: external-secrets
sourceRef:
kind: HelmRepository
name: external-secrets
namespace: flux-system
- version: 0.9.14
+ version: 0.10.3
install:
remediation:
retries: 3
interval: 30m
maxHistory: 2
uninstall: |
bb01b3d
to
5ff08af
Compare
5ff08af
to
ee03f0c
Compare
ee03f0c
to
baf7e7b
Compare
baf7e7b
to
d4b3098
Compare
d4b3098
to
978002c
Compare
978002c
to
2f292bd
Compare
2f292bd
to
b02a9a7
Compare
b02a9a7
to
7b880bf
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.9.14
->0.10.3
Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
external-secrets/external-secrets (external-secrets)
v0.10.3
Compare Source
Image:
ghcr.io/external-secrets/external-secrets:v0.10.3
Image:
ghcr.io/external-secrets/external-secrets:v0.10.3-ubi
Image:
ghcr.io/external-secrets/external-secrets:v0.10.3-ubi-boringssl
What's Changed
0a4eaa0
tobeefdbd
in /hack/api-docs by @dependabot in https://github.com/external-secrets/external-secrets/pull/38840a4eaa0
tobeefdbd
by @dependabot in https://github.com/external-secrets/external-secrets/pull/3886ce46866
to95eb83a
by @dependabot in https://github.com/external-secrets/external-secrets/pull/3887New Contributors
Full Changelog: external-secrets/external-secrets@v0.10.2...v0.10.3
v0.10.2
Compare Source
Image:
ghcr.io/external-secrets/external-secrets:v0.10.2
Image:
ghcr.io/external-secrets/external-secrets:v0.10.2-ubi
Image:
ghcr.io/external-secrets/external-secrets:v0.10.2-ubi-boringssl
What's Changed
Full Changelog: external-secrets/external-secrets@v0.10.1...v0.10.2
v0.10.1
Compare Source
Image:
ghcr.io/external-secrets/external-secrets:v0.10.1
Image:
ghcr.io/external-secrets/external-secrets:v0.10.1-ubi
Image:
ghcr.io/external-secrets/external-secrets:v0.10.1-ubi-boringssl
What's Changed
New Contributors
Full Changelog: external-secrets/external-secrets@v0.10.0...v0.10.1
v0.10.0
Compare Source
Webhook Generator
Webhook generator labels have changed from
generators.external-secrets.io/type: webhook
toexternal-secrets.io/type: webhook
.Webhook Provider
Webhook provider now can only use secrets that are labeled with
external-secrets.io/type: webhook
. This enforces explicit setup for webhook secrets by users.Fixing the issue:
add the label for the secret used by the webhook:
Image:
ghcr.io/external-secrets/external-secrets:v0.10.0
Image:
ghcr.io/external-secrets/external-secrets:v0.10.0-ubi
Image:
ghcr.io/external-secrets/external-secrets:v0.10.0-ubi-boringssl
What's Changed
4197211
toce46866
by @dependabot in https://github.com/external-secrets/external-secrets/pull/3663namespaceRegexes
in full-cluster-secret-store.yaml by @excalq in https://github.com/external-secrets/external-secrets/pull/36818c9183f
to8c9183f
by @dependabot in https://github.com/external-secrets/external-secrets/pull/3687PushSecret
support for Pulumi ESC by @dirien in https://github.com/external-secrets/external-secrets/pull/359777726ef
to0a4eaa0
by @dependabot in https://github.com/external-secrets/external-secrets/pull/37338c9183f
to0d3653d
by @dependabot in https://github.com/external-secrets/external-secrets/pull/37326c27802
toaf9b40f
in /e2e by @dependabot in https://github.com/external-secrets/external-secrets/pull/3734b89d9c9
to0a4eaa0
in /hack/api-docs by @dependabot in https://github.com/external-secrets/external-secrets/pull/3736New Contributors
Full Changelog: external-secrets/external-secrets@v0.9.20...v0.10.0
v0.9.20
Compare Source
Image:
ghcr.io/external-secrets/external-secrets:v0.9.20
Image:
ghcr.io/external-secrets/external-secrets:v0.9.20-ubi
Image:
ghcr.io/external-secrets/external-secrets:v0.9.20-ubi-boringssl
What's Changed
9e458f4
to5f1cd34
by @dependabot in https://github.com/external-secrets/external-secrets/pull/3568aec4784
to9678844
in /e2e by @dependabot in https://github.com/external-secrets/external-secrets/pull/35939bdd569
to6522f0c
by @dependabot in https://github.com/external-secrets/external-secrets/pull/359477726ef
tob89d9c9
in /hack/api-docs by @dependabot in https://github.com/external-secrets/external-secrets/pull/36216522f0c
toace6cc3
by @dependabot in https://github.com/external-secrets/external-secrets/pull/3620Configuration
📅 Schedule: Branch creation - "on saturday" in timezone America/New_York, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.